Article states that encryption was not an option
https://hardware.slashdot.org/story/16/04/01/235238/40-hardware-is-enough-to-hack-28000-police-drones-from-2km-away
Showing posts with label Stupid ideas. Show all posts
Showing posts with label Stupid ideas. Show all posts
Saturday, April 2, 2016
Tuesday, December 15, 2015
The Down side of cloud updates, and how to infuriate your customers
Well, this is a new one, how about a Fortune 100 company, Philips, making a IoT product, Hue, with a tenuous grasp on a small market share makes an open product that seems that in spite of a few warts is pretty good, and getting better, decides to change their strategy?
What if it's to delete the "open" part and only talk to own products, Breaking its functionality for users of existing third party products?
Well, the customers were furious, with light bulbs that they can't turn on, and hopefully, they'll (safely) light their Hue hub on FIRE, send it back to Philips, buy a third party hub and never buy another Philips product again.
I certainly won't.
Note to "bright bulbs" at Philips. (get it? snort). You know the razor blade and handle story. Well this is what you did. You sold a handle and a bunch of blades, and someone else made blades that fit the handle, and you changed the handle so the other peoples blades didn't work, even the ones already bought, and the customer still uses. For some reason, the customer can't have multiple handles, but they can buy a handle from the "other guys", throw yours away, and never buy another blade from you again.
Update: Philips backs down, also from Techdirt, that was quick - https://www.techdirt.com/articles/20151216/07562133099/after-spending-day-as-internets-punching-bag-philips-walks-back-firmware-update-that-locked-out-third-party-products.shtml
What if it's to delete the "open" part and only talk to own products, Breaking its functionality for users of existing third party products?
From Techdirt: Lightbulb DRM: Philips Locks Purchasers Out Of Third-Party Bulbs With Firmware Update
Well, the customers were furious, with light bulbs that they can't turn on, and hopefully, they'll (safely) light their Hue hub on FIRE, send it back to Philips, buy a third party hub and never buy another Philips product again.
I certainly won't.
Note to "bright bulbs" at Philips. (get it? snort). You know the razor blade and handle story. Well this is what you did. You sold a handle and a bunch of blades, and someone else made blades that fit the handle, and you changed the handle so the other peoples blades didn't work, even the ones already bought, and the customer still uses. For some reason, the customer can't have multiple handles, but they can buy a handle from the "other guys", throw yours away, and never buy another blade from you again.
Update: Philips backs down, also from Techdirt, that was quick - https://www.techdirt.com/articles/20151216/07562133099/after-spending-day-as-internets-punching-bag-philips-walks-back-firmware-update-that-locked-out-third-party-products.shtml
Labels:
IOt,
open products,
Philips,
Stupid ideas
Thursday, July 9, 2015
Why Yes, legislators in other countries (especially the EU) are idiots too
Updated: German publishers lost similar cases in 2014 and again in 2015 and are trying again. Basically VG media wants the German government to both require payments from Google for all traffic they send, and to send the traffic too. Good luck with that!
Like Spain, where in Dec 2014 they passed a law requiring all search engines to pay newspapers for snippets and links, whether the newspapers wanted them to or not. Google on December 11 2014 responded with:
Update after reading (more of) the Forbes article: Well. My mistake. 6 months later, Google News ES is still closed. Huh. I guess they don't have a problem with that.
Like Spain, where in Dec 2014 they passed a law requiring all search engines to pay newspapers for snippets and links, whether the newspapers wanted them to or not. Google on December 11 2014 responded with:
"it’s with real sadness that on 16 December (before the new law comes into effect in January) we’ll remove Spanish publishers from Google News, and close Google News in Spain."Techdirt called it the "Nuclear Option", although the rest of us can call it "Duh". What were they thinking?
Update after reading (more of) the Forbes article: Well. My mistake. 6 months later, Google News ES is still closed. Huh. I guess they don't have a problem with that.
Forbes writes on Dec 15th: "That Was Fast; Spain Already In Full Retreat Over Google Tax"
Hopefully the message wasn't lost on Germany, pushing for the same thing again in July 2015
Oh well, here goes Spain again, going full police state on everyone, banning demonstrations and taking pictures of police.
That's almost as stupid as banning outdoor photography. More at I'm a Photographer not a Terrorist
Perry
PS. Oh and patch your systems too
Thursday, January 29, 2015
Oracle Java installs Malware Toolbar without "Ask"ing
Updates after Java 7 Update 71 don't appear to allow opting-out of Ask toolbar.
It does let you choose whether to use Ask as the default search engine, and another thing, but the Ask toolbar looks like it's automatic
I'll just delete java then
Do they really need the money? Will Java stop being free?
It's really time to get completely off the Java platform.
It does let you choose whether to use Ask as the default search engine, and another thing, but the Ask toolbar looks like it's automatic
I'll just delete java then
Do they really need the money? Will Java stop being free?
It's really time to get completely off the Java platform.
Tuesday, November 18, 2014
Awesome! Uber crying that media is mean to them, suggests "Digging up dirt on journalists"
Update #7 - 20-June because AUATT (below) - The FTC is investigating them?
Update #6 - 14-June-2017 - As a matter of fact, this blog is "All Uber all the time". After Emil Michael's and Travis Kalanick's LOA departures, board member David Bonderman in a discussion with Adriana Huffington - 'who was speaking about the need for more female representation on Uber’s board. When “there’s one woman on the board, it’s much more likely that there will be a second woman on the board,” Huffington said, to which Bonderman shot back “what it shows is that it’s much more likely to be more talking.” - Bonderman was out in about the time it takes to say "Do we need to call security?"
Update #5 - 12-June-2017 - Eric Holder report released soon, likely not good. Travis Kalanick on LOA after a family tragedy (we're truly sorry and our thoughts and prayers for the family), oh, and Emil Michael out
Update #4: The Verge: Can Uber be saved from itself?
Watch for: Ryan Graves (employee #1) to take the fall for the latest things, both the Misogyny from Susan Fowlers blog (sub watch - are they investigating her personally? ) and Greyball (Verge again)
Update #3a:
Uber allegedly has a pretty horrible culture of sexual harassment, per engineer-author Susan Fowler who isn't afraid to blow the whistle under her own name, and there's a really good blog post at Global Nerdy that deconstructs and validates the claims
Kara Swisher from Recode/Decode had a podcast about Uber
that posted the day after Susan’s blog post went viral named “Self-driving
cars are an ‘existential crisis’ for Uber, ‘Upstarts’ author Brad Stone says”
Here’s Kara’s blog post about the leather jacket
Update #2: CNN- Uber limits employee access to God mode
Update #1: Washington Post blog has insight on their privacy and least privilege policy
AKA - Let's DOX our customers, that'll show them
So correct me if I'm wrong, Buzzfeed article, linked from Drudge:
According to Buzzfeed article uber-executive-suggests-digging-up-dirt-on-journalists :
- Uber thinks journalists are being mean, especially pando writer Sarah Lacey writing about them after a Buzzfeed article accusing them of sexism (awesome example of just that BTW)
- VP of
Black Bag Jobs, er "business", Emil Michael, suggests opposition research including aforementioned digging up dirt - Immediate spin control, an Uber spokes droid states (from the article) "the company does not do “oppo research” of any sort on journalists, and has never considered doing it. She also said Uber does not consider Lacy’s personal life fair game, or believe that she is responsible for women being sexually assaulted."
- Even though (from the article again) "the general manager of Uber NYC accessed the profile of a BuzzFeed News reporter, Johana Bhuiyan, to make points in the course of a discussion of Uber policies."
- SO a new economy taxi company is on record of using it's data against journalists and anybody still uses them?!
- Update: Amy Keyishian at Re/code had the first link to Seth Meyers clip with the "That Boober Guy" nickname for Travis Kalanick, some great advice on the difference in truth in public and private speech, and equating the Emil Michael quotes with Valdemort speaking to Hogwarths.
Labels:
Privacy,
Sexism,
Stupid ideas,
Uber
Tuesday, October 28, 2014
Good Techdirt analysis of Applepay and CurrentC situation
States that retailers want to cut out Mastercard and Visa, and want ultimate tracking of their customers that they had when they used their old tracking cards
https://www.techdirt.com/articles/20141027/07065628950/payment-wars-how-merchants-carriers-are-trying-to-block-payment-systems-they-cant-track.shtml
Grab the popcorn, IMHO, this will be an utter and dismal failure, because the members of PCI won't correctly use their previous lessons learned to make a system that protects customers, instead they will greedily grab all the data they can on their customers, attempt to protect their shopkeeper members, but fail because they're cheaping out on the infrastructure, creating something even worse than PCI.
Seriously, Rite Aid and CVS are creating a payment system that will be more secure than Google, Apple and Mastercard/VISA? OMG what are they thinking other than sheer greed. I won't boycott, though, expecially CVS, I truly want to support a company that went out on a limb and stopped selling tobacco.
Don't use CurrentC, it will be even riskier than debit cards - the QR codes will be found to be awful security, and there will be people burned by the automatic debit behavior of the system. Even if they use something clever like Steve Gibson's SQRL , they won't be able to implemment something secure enough to handle the amounts of cash it needs to.
Please just use credit cards or cash at these merchants
https://www.techdirt.com/articles/20141027/07065628950/payment-wars-how-merchants-carriers-are-trying-to-block-payment-systems-they-cant-track.shtml
Grab the popcorn, IMHO, this will be an utter and dismal failure, because the members of PCI won't correctly use their previous lessons learned to make a system that protects customers, instead they will greedily grab all the data they can on their customers, attempt to protect their shopkeeper members, but fail because they're cheaping out on the infrastructure, creating something even worse than PCI.
Seriously, Rite Aid and CVS are creating a payment system that will be more secure than Google, Apple and Mastercard/VISA? OMG what are they thinking other than sheer greed. I won't boycott, though, expecially CVS, I truly want to support a company that went out on a limb and stopped selling tobacco.
Don't use CurrentC, it will be even riskier than debit cards - the QR codes will be found to be awful security, and there will be people burned by the automatic debit behavior of the system. Even if they use something clever like Steve Gibson's SQRL , they won't be able to implemment something secure enough to handle the amounts of cash it needs to.
Please just use credit cards or cash at these merchants
Monday, October 27, 2014
Truth finally? Rutgers paper about e-voting - Don't do it
Slashdot talked about a paper generated when Rutgers university did an analysis of the emergency e-voting that was done after hurricane Sandy, and it was apparently another disaster.
Just pulling interesting things from the table of contents:
VII. INTERNET VOTING IS NOT SAFE, SHOULD NOT BE MADE LEGAL, AND SHOULD NEVER BE INCORPORATED INTO EMERGENCY MEASURES
VIII. INTERNET ATTACKS ON U.S. INFRASTRUCTURE AND BUSINESSES ARE SO PREVALENT THAT IT IS NAÏVE TO BELIEVE THAT U.S.ELECTIONS WOULD NOT BE OF INTEREST TO HACKERS
So let's jump right to the conclusion:
CONCLUSION
After Superstorm Sandy, there was no structure in place to make sure that emergency voting directives were followed. There was mass confusion among county officials and voters, alike. Emergency measures such as Internet and fax voting not only violated New Jersey law, but also left votes vulnerable to on-line hacking. Internet voting should never be permitted, especially in emergencies when governmental infrastructure is already compromised.
As the May 2014 National Climate Assessment issued by the U.S. government makes all too clear, New Jersey is highly likely to be impacted negatively by more Superstorm Sandy-like disasters in the near future.265 This means that it is critical for New Jersey to enact and implement emergency voting procedures that comply with existing election law, and that protect every vote. As such, those emergency measures should not include Internet and fax voting as an option, under any circumstance.
Labels:
Government,
online voting,
Stupid ideas
Wednesday, June 4, 2014
Wow. Just wow. Our President.
From TheHill.com:
WH apologizes to Senate intel chief for prisoner swap secret
The White House has apologized to Senate Intelligence Committee Chairwoman Dianne Feinstein (D-Calif.) for failing to alert her in advance of a decision to release Taliban commanders from Guantanamo Bay.
Feinstein told reporters that she received a call from Deputy National Security Adviser Tony Blinken on Monday evening apologizing for what the administration is calling an “oversight.”
From TheHill.com:And now, just 4 days later, Dems start bailing
Senate Democrats Go AWOL
They had Obama's back on the Bergdahl/Taliban trade. Now they're walking away.
Even ABC News Admits the Taliban is a Terrorist Organization
Labels:
Attacks. Global Internet,
Politics,
Stupid ideas,
White House
Wednesday, April 30, 2014
$48K Penalty Proposed Against Individual in Cell Jammer Investigation
Hmm, somebody sits by the side of a highway and uses a radio
transmitter gadget to cause mayhem?
Naaah. Too unrealistic.
http://www.fcc.gov/document/48k-penalty-proposed-against-individual-cell-jammer-investigation-0
Oh, and BTW - he did it for *2 years!*
Naaah. Too unrealistic.
http://www.fcc.gov/document/48k-penalty-proposed-against-individual-cell-jammer-investigation-0
Oh, and BTW - he did it for *2 years!*
Wednesday, April 23, 2014
Happy Easter! Software caught making bad router firmware
According to ARS and Slashdot, this software provider for router makers gave us a nasty Easter Egg
When confronted, they patched it with something that obfuscated but not closed it
When confronted, they patched it with something that obfuscated but not closed it
Labels:
backdoors,
Stupid ideas,
Web Safety
Tuesday, March 25, 2014
Google: Another update, Pando shows that Google joined a cartel forcing down IT workers wages
According to Pando Daily, Google, Apple and a host of other companies got together, and made a list of companies that wouldn't call each other for tech workers. How nice. There is even (email) evidence of at least 1 recruiter who lost his job for being overly aggressive in, umm, recruiting, at a company he wasn't supposed to touch, but wasn't told until, well, he might've got the hint at the same time he was walked out.
The whole list (from Pando again) is:
The whole list (from Pando again) is:
• Apple, IncAnd might have gotten as far as a million workers. There's an antitrust lawsuit in the works, scheduled for May, but things are settling out of court. Seeing as some of this is serious, of course there are out of court settlements.
• Comcast Corporation
• DoubleClick
• Genentech
• IBM Corporation (Junior hires okay—also applies to subsidiaries)
• Illumita
• Intel Corporation
• Intuit
• Microsoft
• Oglivy
• WPP
Labels:
Apple,
Comcast,
Google,
Stupid ideas
Monday, March 17, 2014
Google: That whole "don't be evil" thing is so last century!
According to Edweek.org, The latest thing in Google slide to become the great evil empire is the "Google Apps for Education".
Apparently Google has these free applications that schools can sign up for, and then require their students to use. Then Google scans the content learning all kinds of things about the students.
Why do I think that's a problem? Well, let's see what happens in a class action lawsuit in San Jose, which Judge Lucy H Koh denied Googles motion to dismiss the case and is not deciding whether to certify it as a class. (Google Inc. Gmail Litigation, 13-md-02430.)
Also, there's FERPA, the "Family Educational Rights and Privacy Act", which is meant to protect students privacy, and gives the following example:
How about Microsoft Office 365?
Apparently Google has these free applications that schools can sign up for, and then require their students to use. Then Google scans the content learning all kinds of things about the students.
Why do I think that's a problem? Well, let's see what happens in a class action lawsuit in San Jose, which Judge Lucy H Koh denied Googles motion to dismiss the case and is not deciding whether to certify it as a class. (Google Inc. Gmail Litigation, 13-md-02430.)
Also, there's FERPA, the "Family Educational Rights and Privacy Act", which is meant to protect students privacy, and gives the following example:
EXAMPLE 4: A district contracts under the school official exception with a provider for basic productivity applications to help educate students: email, calendaring, web-search, and document-collaboration software. The district sets up the user accounts, using basic enrollment information (name, grade, etc.) from student records. Under FERPA, the provider may not use data about individual student preferences gleaned from scanning student content to target ads to individual students for clothing or toys, because using the data for these purposes was not authorized by the district and does not constitute a legitimate educational interest as specified in the district’s annual notification of FERPA rights.Yes, right, which is exactly what Google does with Gmail, and they state they make no secret of. Except they're not contracting with adult users of the services, they're contracting with schools that require minor students to use the applications.
How about Microsoft Office 365?
The privacy policy for Microsoft’s Office 365, the company’s competitor product for Google Apps for Education, states “We do not mine your data for advertising purposes. It is our policy to not use your data for purposes other than providing you productivity services.”Score 1 for Microsoft
Labels:
FERPA,
Google,
Microsoft,
Privacy,
Stupid ideas
Wednesday, October 30, 2013
Rep Mike Rogers (R-Mich) actually said this:
"You can't have your privacy violated if you don't know your privacy is violated"
Then he was incredulous when law professor Stephen Vladeck disagreed with him "If a tree falls in the forest, it makes a noise whether you're there to see it or not"
"That's a new interesting standard in the law, we're gonna have this conversation and we're gonna have wine, that's gonna get a lot more interesting"
The possibilities are endless.
There's a really good write-up in Techdirt
A good parody article in Popehat too
Then he was incredulous when law professor Stephen Vladeck disagreed with him "If a tree falls in the forest, it makes a noise whether you're there to see it or not"
"That's a new interesting standard in the law, we're gonna have this conversation and we're gonna have wine, that's gonna get a lot more interesting"
The possibilities are endless.
There's a really good write-up in Techdirt
A good parody article in Popehat too
Labels:
Freedom,
Law,
NSA,
Politics,
Stupid ideas
Thursday, October 10, 2013
Updated! Wikipedia Sockpuppets lead to Scam on paid Wikipedia entries
Very interesting article on the DailyDot talks about a huge (apparent) network of fake people editing wikipedia entries. It seems to lead to a paid wikipedia editing service.
It gets really interesting when they discuss that:
Update 10/22/2013: In Ars Technica, Joe Mullin discusses the deletion of 250 PR-firm-linked user accounts
It gets really interesting when they discuss that:
- It's forbidden to edit wikipedia entries for money, and hugely frowned on to edit your own
- Wikipedia admins (may) work at some/most/all of the services
- The kicker - potential clients get their pages modified or deleted before sales calls
Update 10/22/2013: In Ars Technica, Joe Mullin discusses the deletion of 250 PR-firm-linked user accounts
Labels:
Hacking,
Identity Protection,
scams,
Stupid ideas
Thursday, March 7, 2013
Tuesday, March 5, 2013
WHAT, you think you can do drone strikes in the US?!
From Eric "Good Prosecutorial Discretion" Holder, US Atty General, March 2013:
“It is possible, I suppose, to imagine an extraordinary circumstance in which it would be necessary and appropriate under the Constitution and applicable laws of the United States for the President to authorize the military to use lethal force within the territory of the United States,” Holder replied in a letter yesterday to Paul’s question about whether Obama “has the power to authorize lethal force, such as a drone strike, against a U.S. citizen on U.S. soil, and without trial.”
From Wikipedia:
Posse Comitatus Act
"...Any use of the Armed Forces under either Title 10/Active Duty or Title 10/Reserves at the direction of the President will offend the Constitutional Law also known as Public Law prohibiting such action unless declared by the President of the United States and approved by Congress."Umm Holder? HOLDER! BUELLER?!?!
Even our president can't authorize drone strikes on US soil against Americans.
(I hope!)
|
Labels:
Freedom,
Politics,
Stupid ideas,
TSA
Wednesday, November 14, 2012
App maker thinks it's OK to hijack your twitter account
If they think you've pirated the app, Enfour will use your Twitter credentials and post a confession.
I know what Apps that do (really) unexpected things are called - "Malware". And I'll accuse them of that, just on my blog though.
This is the problem with apps that take your credentials from other services, you never know what they'll do with them until it's too late.
I know what Apps that do (really) unexpected things are called - "Malware". And I'll accuse them of that, just on my blog though.
This is the problem with apps that take your credentials from other services, you never know what they'll do with them until it's too late.
Sunday, November 11, 2012
Don't buy toshiba laptops
Blah - I don't know what it is with some of these companies, but Toshiba shut down a blogger that put their repair manuals online. This simply means that they'll cost that much more to repair, or if an authorized center won't fix it at all, you're out of luck
There are way more manufacturers out there
There are way more manufacturers out there
Friday, November 9, 2012
The Privacy Racket
I performed a vanity search a minute ago, to see how easy it was to link a username to my real identity, and I came across "mylife.com", which showed my name, town, age, and my immediate family's names and ages. If I wanted to remove my information on line, I had to create an acocunt and gice them more information. Great. so I called them on the telephone.
They quickly removed my information with a minimum of additional information, they only verified my previous address (!).
Then the kicker. The nice woman on the telephone informed me about all the places with public information on the web, and how difficult it would be to call them all. On the other hand, there was a great service called "Safe Shepherd" which would make all those telephone calls for me for only $60 per year!
Such a deal! Racket? Scam? whatever. sheesh. what will they think of next?
According to Wikipedia they have a free service too - wonder why the nice young lady didn't mention that?
Perry
They quickly removed my information with a minimum of additional information, they only verified my previous address (!).
Then the kicker. The nice woman on the telephone informed me about all the places with public information on the web, and how difficult it would be to call them all. On the other hand, there was a great service called "Safe Shepherd" which would make all those telephone calls for me for only $60 per year!
Such a deal! Racket? Scam? whatever. sheesh. what will they think of next?
According to Wikipedia they have a free service too - wonder why the nice young lady didn't mention that?
Perry
Monday, November 5, 2012
When you want something real bad...
That's exactly what you get.
Or, "What's worse than online voting? How about email voting?" WHAT COULD THEY POSSIBLY BE THINKING?
Yes kids, this is not The Onion , but someone in New Jersey thinks you can securely create an online voting system in a week, and use email.
Hello, HELLO?! Read this - yes "recoil in horror" - ( his words ).
This is not "Which Jersey Shore member are you most like?" This is for the COMMANDER IN CHIEF OF THE MOST POWERFUL COUNTRY IN THE WORLD.
There are truly bad people out there that want to steal the election, and they have WAY MORE RESOURCES than (bleeping) NEW JERSEY in the MIDDLE OF THE WORST DISASTER maybe EVER!
Please don't do this!
Perry
Or, "What's worse than online voting? How about email voting?" WHAT COULD THEY POSSIBLY BE THINKING?
Yes kids, this is not The Onion , but someone in New Jersey thinks you can securely create an online voting system in a week, and use email.
Hello, HELLO?! Read this - yes "recoil in horror" - ( his words ).
This is not "Which Jersey Shore member are you most like?" This is for the COMMANDER IN CHIEF OF THE MOST POWERFUL COUNTRY IN THE WORLD.
There are truly bad people out there that want to steal the election, and they have WAY MORE RESOURCES than (bleeping) NEW JERSEY in the MIDDLE OF THE WORST DISASTER maybe EVER!
Please don't do this!
Perry
Labels:
online voting,
Stupid ideas,
WCPGR
Subscribe to:
Posts (Atom)